Impact
The vulnerability is a heap‑based buffer overflow in Microsoft Standard XPS, triggered by an authorized network attacker to gain higher privileges. The flaw arises from improper bounds checking during buffer handling, enabling attacker‑controlled data to overwrite adjacent memory. This can lead to arbitrary code execution with elevated rights, compromising system confidentiality and integrity.
Affected Systems
Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 releases 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both full and core installations.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate‑to‑high severity. The EPSS score is not available, so the exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The documented attack vector is an authorized attacker over the network, implying that compromised credentials or system access are required to trigger the overflow.
OpenCVE Enrichment